2026 CVE Vulnerabilities

64,616 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42728HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Cont...
CVE-2026-42727CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ...
CVE-2026-42726MEDIUM6.5Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Explo...
CVE-2026-42725MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout...
CVE-2026-3349MEDIUM6.1The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o...
CVE-2026-3348MEDIUM4.4The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D...
CVE-2026-3012MEDIUM6.8A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl...
CVE-2026-2288MEDIUM4.8The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all ...
CVE-2026-2280MEDIUM4.8The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t...
CVE-2026-8054CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints ...
CVE-2026-49002CRITICAL9.1Access control failure means that an application does not effectively check user access permissions, so that unauthorize...
CVE-2026-48968MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid...
CVE-2026-48877MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive...
CVE-2026-40852HIGH7.2A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. T...
CVE-2026-40851HIGH8.4A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to...
CVE-2026-40850HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData func...
CVE-2026-40849HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile vi...
CVE-2026-40848HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr...
CVE-2026-40847HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ...
CVE-2026-40846HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to i...
CVE-2026-40845HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuratio...
CVE-2026-40844HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due t...
CVE-2026-40843HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to...
CVE-2026-40842HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi...
CVE-2026-40841HIGH7.1An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now